mcptrustchecker_
How it scans Trust Score Scoring FAQ MCP Trust Registry Blog
API Star
How it scans Trust Score Scoring FAQ MCP Trust Registry Blog API
Home / Privacy Policy

Privacy Policy

Last updated: July 21, 2026

MCP Trust Checker is a free, non-commercial, open-source project run by its maintainers. There are no user accounts, no payments, no advertising profiles, and we never sell or rent personal data. This page explains the little data the Service does touch, why, and what your choices are. Contact for anything privacy-related: [email protected].

1. Summary

  • Browsing the site or the Registry: no registration, no personal data required.
  • Requesting an API key: you give us an email address and a short description of your use case.
  • Using the API: we count requests per key and keep short-lived technical logs.
  • The CLI scanner: runs on your machine, sends us nothing — no telemetry of any kind.
  • We never sell personal data and we collect nothing beyond what this page lists.

2. What we collect and why

  • API access requests. Email address, an optional use-case description and expected volume — used solely to issue, operate and, where necessary, contact you about your API key (for example before revoking an abusive key). Basis: taking steps you request / running the service you asked for.
  • Technical server logs. IP address, user agent, requested URL, timestamp and response status — kept briefly for security, abuse prevention and debugging (our legitimate interest in keeping a free service running), then deleted or rotated automatically.
  • API usage counters. Per-key request counts and last-used timestamps, to enforce fair-use limits.
  • Anti-bot check. The API request form is protected by Cloudflare Turnstile, which processes technical browser signals to distinguish humans from bots.
  • Analytics. We use Google Analytics 4 and Ahrefs Analytics to understand aggregate site usage (pages viewed, approximate region, browser type). See Section 5 for cookies and opt-outs.
  • Email. If you write to [email protected] we keep the correspondence for as long as needed to handle and document the request.

We do not knowingly collect any special categories of data, and the Service is not directed at children. We do not use personal data for automated decision-making about people or for profiling.

3. Public package data

The Registry and the scanner process publicly available software package data from public registries such as npm and PyPI: package names, versions, manifests, published code and public metadata. Such metadata can incidentally include personal data that its publishers chose to make public (for example a maintainer username or a public author email inside a package manifest). We process it because running an open, reproducible security resource for the ecosystem is a legitimate interest, we only mirror what is already public, and we do not enrich or combine it into profiles of people. If you are a package author and want a listing corrected or removed, email [email protected] — see the Terms of Use for the process.

4. Who else touches the data

We use a small number of infrastructure providers that process data on our behalf: our hosting provider (the server the site runs on), Cloudflare (DNS/proxy and the Turnstile anti-bot check), Google (Analytics) and Ahrefs (analytics). Each receives only what its function requires. Some of these providers may process data outside your country; where that happens, transfers rely on the safeguards those providers offer (such as standard contractual clauses). We never sell, rent or trade personal data, and we do not share it with anyone else except where the law obliges us to.

5. Cookies and analytics choices

The site itself sets no cookies for its own features — there is no login and no personalisation. Google Analytics may set its usual measurement cookies; Ahrefs Analytics is designed to work without cookies. You can refuse or delete cookies in your browser, use a content blocker (the site works fully with analytics blocked), enable “Do Not Track”, or install Google's Analytics opt-out add-on. None of this affects any functionality of the Service.

6. How long we keep data

  • Technical logs — days to a few weeks, rotated automatically.
  • API key records (email, use case, counters) — while the key exists; deleted on request together with the key.
  • Support correspondence — as long as needed to handle the matter.
  • Aggregate analytics — per the analytics providers' standard retention.

7. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Because we hold so little, exercising them is simple: email [email protected] and we will act on the request without undue delay — including deleting your API key and its associated email entirely. You also have the right to complain to the data-protection authority responsible for you.

8. Security

The Service runs over HTTPS; API keys are stored only as cryptographic hashes (the plaintext key is shown once to its owner and cannot be recovered from our database); admin access is restricted and authenticated; the scanning process runs sandboxed with minimal privileges. No system is perfectly secure, but the design keeps the amount of personal data at risk deliberately minimal.

9. Changes to this policy

If the Service ever starts collecting something new, this page will be updated first, with a new “Last updated” date. The current version is always at this address.

10. Contact

[email protected] — the maintainers of mcptrustchecker.com. See also the Terms of Use.

mcptrustchecker
GitHub npm Methodology Rules MIT License Contact Terms of Use Privacy
Free open-source MCP security scanner for Model Context Protocol servers · offline & deterministic
© 2026 MCP Trust Checker contributors · [email protected]